0Pricing
Spring Security 6 & JWT Authentication · 课时

理解 Spring Security 过滤器链

深入了解 Spring Security 6 的内部机制,理解 Servlet 过滤器链如何处理每个请求,以及身份验证在其中所处的位置

理解 Spring Security 过滤器链 是 CoddyKit 上的免费 Spring Security 6 & JWT Authentication 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Security 6 & JWT Authentication 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

How Requests Get Secured

So how does every request actually get checked? The security filter chain — a series of servlet filters Spring slots in before your controllers.

What Is a Servlet Filter?

A servlet Filter intercepts HTTP requests and responses before they reach your code. Spring Security is built almost entirely from these filters.

The DelegatingFilterProxy

The real servlet filter, DelegatingFilterProxy, hands each request to a Spring-managed bean — bridging the servlet world and the Spring context.

The FilterChainProxy

Behind that proxy sits FilterChainProxy, which holds one or more SecurityFilterChain instances and routes each request to the one that matches.

Key Filters in Order

Filters run in a fixed order: SecurityContextHolderFilter loads context, the auth filter handles login, and AuthorizationFilter enforces access rules.

Defining a SecurityFilterChain Bean

In Spring Security 6 you configure everything by declaring a SecurityFilterChain bean — the modern replacement for WebSecurityConfigurerAdapter. See below.

@Bean
SecurityFilterChain chain(HttpSecurity http) throws Exception {
    http.authorizeHttpRequests(a -> a.anyRequest().authenticated())
        .formLogin(Customizer.withDefaults());
    return http.build();
}

Where the SecurityContext Lives

After login, the Authentication is stored in the SecurityContext and stays reachable via SecurityContextHolder for the rest of the request.

Authentication auth = SecurityContextHolder.getContext().getAuthentication();

Permitting Some Paths

Let public paths through while securing the rest — all on the same chain. The code uses permitAll() for /public and authenticated() for everything else.

http.authorizeHttpRequests(a -> a
    .requestMatchers('/public/**').permitAll()
    .anyRequest().authenticated());

Multiple Filter Chains

Register several SecurityFilterChain beans with securityMatcher so API and web paths get different rules. The first matching chain wins.

http.securityMatcher('/api/**');

Adding a Custom Filter

Slot your own filter at a precise position with addFilterBefore — the foundation for the JWT processing you'll build later in this course.

http.addFilterBefore(myFilter, UsernamePasswordAuthenticationFilter.class);

Why This Matters

Knowing the chain explains why ordering matters, where auth versus authz happens, and exactly where a custom JWT filter has to plug in.

Quick Check

In Spring Security 6, how do you define your security configuration?

Recap

Recap: requests flow DelegatingFilterProxy to FilterChainProxy to SecurityFilterChain; filters run in order, auth then authz, and addFilterBefore inserts custom ones.

常见问题解答

「理解 Spring Security 过滤器链」课时是免费的吗?

是的 — 「理解 Spring Security 过滤器链」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Security 6 & JWT Authentication 课程的其余内容,请升级到 CoddyKit PRO。 Spring Security 6 & JWT Authentication 课程共包含 4 节课。

「理解 Spring Security 过滤器链」这节课中我会学到什么?

深入了解 Spring Security 6 的内部机制,理解 Servlet 过滤器链如何处理每个请求,以及身份验证在其中所处的位置 你通过在浏览器中直接运行的动手代码来练习 Spring Security 6 & JWT Authentication,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Security 6 & JWT Authentication 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Security 6 & JWT Authentication 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。

「理解 Spring Security 过滤器链」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Security 6 & JWT Authentication 课中编写并运行代码吗?

能。每节 Spring Security 6 & JWT Authentication 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. Spring Security 6 入门
  2. 项目设置与依赖
  3. 内存用户身份验证
  4. 理解 Spring Security 过滤器链
← 返回 Spring Security 6 & JWT Authentication